[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-203819-105":59,"doc-detail-203819-en":130},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":123,"head_meta":125,"extra_data":127,"updated_unix":129},105,"en","a-certificate-poisoning-resistant-protocol-for-the-synchronization-of-web-of-trust-networks-doctoral-thesis","A certificate-poisoning-resistant protocol for the synchronization of Web of Trust networks - Doctoral Thesis","","A fundamental issue in encrypted network communications is establishing trust in the counterpart’s identity. This is commonly addressed through trust distribution models, where the decentralized Web of Trust approach shows notable weaknesses. One critical weakness, certificate poisoning, has pushed the main OpenPGP certificate keyserver network toward unsustainable operation. This thesis introduces a key certification and synchronization protocol that prevents certificate-poisoning effects while maintaining as much compatibility as possible with existing OpenPGP and HKP toolsets.",{"@graph":69,"@context":122},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/a-certificate-poisoning-resistant-protocol-for-the-synchronization-of-web-of-trust-networks-doctoral-thesis/203819/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/a-certificate-poisoning-resistant-protocol-for-the-synchronization-of-web-of-trust-networks-doctoral-thesis/203819.png","ImageObject",300,407,{"name":92,"@type":93},"\tJames","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-09-18","2026-09-04",true,{"@type":102,"interactionType":103,"userInteractionCount":8},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118],{"name":109,"@type":110,"acceptedAnswer":111},"What problem does the thesis address in encrypted communications?","Question",{"text":112,"@type":113},"It addresses the challenge of ensuring trust in the counterpart’s identity. Encrypted endpoints must verify identity to prevent impersonation by a hostile third party.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"How does certificate poisoning affect the OpenPGP keyserver network?",{"text":117,"@type":113},"Certificate poisoning is identified as a major weakness that harms sustainability of the main OpenPGP certificate keyserver network, pushing it to critical limits.",{"name":119,"@type":110,"acceptedAnswer":120},"What does the proposed protocol aim to achieve?",{"text":121,"@type":113},"The thesis presents a key certification and synchronization protocol that avoids the harmful effects of certificate poisoning. It also aims to retain compatibility with existing OpenPGP and HKP toolsets as much as possible.","https://schema.org",{"og:url":83,"og:type":124,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":126,"canonical":83},"index,follow",{"doc_id":128,"site_id":62},203819,1788564105,{"code":4,"msg":5,"data":131},{"doc_id":128,"user_id":132,"nickname":92,"user_avatar":133,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":8,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":139,"language":140,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":67,"update_tm":129,"read_time":144},2336474466412,"https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d","Universidad Nacional Autónoma de México  \nPosgrado en Ciencia e Ingeniería de la Computación  \nA certificate-poisoning-resistant protocol for the synchronization of Web of Trust  \nnetworks  \ntesis  \nque para optar por el grado de:  \nDoctor en Ciencia e Ingeniería de la Computación  \nPresenta:  \nGunnar Eyal Wolf Iszaevich  \nTutor:  \nDr. Jorge Luis Ortega Arjona  \nFacultad de Ciencias, UNAM  \nCiudad Universitaria, Febrero de 2025  \nContents  \nAbstract 4  \n1 Introduction 5  \n1.1 Context ................................ 5  \n1.2 Problem statement .......................... 5  \n1.3 Hypothesis .............................. 6  \n1.4 Approach ............................... 7  \n1.5 Contributions ............................. 7  \n1.6 Structure ............................... 7  \n2 Background 9  \n2.1 Terminology .............................. 9  \n2.2 Encrypted communications ..................... 11  \n2.2.1 Private key cryptography .................. 12  \n2.2.2 Public key cryptography ................... 12  \n2.3 Trust distribution models ...................... 14  \n2.3.1 Public Key Infrastructure Certificate Authorities (PKICAs) .............................. 15  \n2.3.2 Web of Trust (WoT) ..................... 15  \n2.3.3 Trust On First Use (TOFU) ................. 17  \n2.4 Key distribution ........................... 19  \n2.4.1 The HKP public keyserver network ............. 20  \n2.5 Notable implementations ....................... 21  \n2.5.1 Transport Layer Security (TLS) .............. 21  \n2.5.2 OpenPGP ........................... 21  \n2.6 Attacks and weaknesses on transitive trust models ........ 23  \n2.6.1 Lack of user understanding of the model .......... 23  \n2.6.2 Forgery or theft of CA keys ................. 24  \n2.6.3 The user interface is to blame: Evil32 ........... 27  \n2.6.4 Key UID information for storing arbitrary information .. 31  \n2.6.5 Lack of use of the trust model ................ 32  \n2.6.6 Certificate poisoning ..................... 33  \n2.7 Summary ............................... 34  \n3 Related work 35  \n3.1 Abuse-Resistant OpenPGP Keystores ............... 35  \n3.2 Key discovery mechanisms ...................... 36  \n3.2.1 DNS-based Authentication of Named Entities (DANE) for OpenPGP ........................... 37  \n3.2.2 OpenPGP Web Key Directory (WKD) ........... 39  \n3.2.3 TOFU for OpenPGP ..................... 40  \n3.2.4 Autocrypt ........................... 41  \n3.2.5 ClaimChain .......................... 42  \n3.3 Analysis on the full keyserver data set ............... 43  \n3.3.1 Search for key weaknesses .................. 44  \n3.3.2 Threat models to jeopardize the WoT functionality .... 44  \n3.4 Improvements over the HKP keyserver network .......... 46  \n3.4.1 BlockPGP: a Blockchain-based Framework for PGP Key Servers ............................ 46  \n3.4.2 The PEAKS keyserver .................... 48  \n3.4.3 Keyserver synchronization without prior context ..... 50  \n3.4.4 [keys.openpgp.org](keys.openpgp.org) and Hagrid, Keeper of Keys .... 51  \n3.4.5 Efficient and private certificate updates .......... 52  \n3.5 Moving away from OpenPGP .................... 53  \n3.5.1 Off-the-Record Communication ............... 54  \n3.5.2 Assessing OpenPGP itself: hints of deeper issues ..... 55  \n3.6 Summary ............................... 58  \n4 A proposal for a certificate-poisoning-resistant protocol 60  \n4.1 Assessment of the magnitude of the problem ............ 60  \n4.1.1 A previous study on the SKS keyserver network status .. 61  \n4.1.2 An interpretation of the HKP key exchange protocol ... 64  \n4.2 First-party attested third party certification protocol ....... 65  \n4.3 Protocol walk-through ........................ 67  \n4.4 Summary ............................... 69  \n5 Implementation, validation and results 70  \n5.1 Implementing the protocol ...................... 70  \n5.1.1 Certificate attestation under Sequoia ............ 71  \n5.1.2 The attestation as OpenPGP packet-level data ...... 73  \n5.1.3 Code modificat","cbCaimh3VOMz6atc","https://ap.wps.com/l/cbCaimh3VOMz6atc","pdf",3313276,118,"English","# Abstract\n# Introduction\n## Context\n## Problem statement\n## Hypothesis\n## Approach\n## Contributions\n## Structure\n# Background\n## Terminology\n## Encrypted communications\n## Trust distribution models\n## Key distribution\n## Notable implementations\n## Attacks and weaknesses on transitive trust models\n## Summary\n# Related work\n## Abuse-Resistant OpenPGP Keystores\n## Key discovery mechanisms\n## Analysis on the full keyserver data set\n## Improvements over the HKP keyserver network\n## Moving away from OpenPGP\n## Summary\n# A proposal for a certificate-poisoning-resistant protocol\n## Assessment of the magnitude of the problem\n## First-party attested third party certification protocol\n## Protocol walk-through\n## Summary\n# Implementation, validation and results\n## Implementing the protocol\n## Validation\n## Summary\n# Conclusions\n## Summary of the research work\n## Hypotesis restatement\n## Contributions restatement\n## Comparison\n## Future work","[{\"question\":\"What problem does the thesis address in encrypted communications?\",\"answer\":\"It addresses the challenge of ensuring trust in the counterpart’s identity. Encrypted endpoints must verify identity to prevent impersonation by a hostile third party.\"},{\"question\":\"How does certificate poisoning affect the OpenPGP keyserver network?\",\"answer\":\"Certificate poisoning is identified as a major weakness that harms sustainability of the main OpenPGP certificate keyserver network, pushing it to critical limits.\"},{\"question\":\"What does the proposed protocol aim to achieve?\",\"answer\":\"The thesis presents a key certification and synchronization protocol that avoids the harmful effects of certificate poisoning. It also aims to retain compatibility with existing OpenPGP and HKP toolsets as much as possible.\"}]","A certificate-poisoning-resistant protocol for the synchronization of Web of Trust networks - Doctoral Thesis | PDF",297]